AI Policy Wiki
Dashboard

AI and Tort Liability

medium confidence · updated 2026-08-08

Tort, product-liability, and consumer-protection law as a governance mode for AI — shifting costs of AI failures back to deployers, developers, and vendors via courts rather than regulators. Anchored to companion-chatbot harms litigation (Raine, Garcia, PA v. Character.AI), copyright suits, and the emerging product-liability theory for AI agents.

AI and tort liability refers to the use of tort, product-liability, and consumer-protection law as a governance mode for AI. Unlike pre-release vetting or procurement-driven governance, which act upstream of deployment, liability governance acts downstream, shifting the costs of AI-caused harms back to the responsible party through courts and class actions. The substance of this approach is developed across the relevant litigation and analysis pages; the active legal theories are summarized below.

Theories under test

Several distinct liability theories are being tested in active or emerging litigation.

Companion-chatbot harm. A cluster of US suits advances wrongful-death, deceptive-practices, and impersonation-of-a-licensed-professional theories against companion-chatbot operators, including Raine v. OpenAI, Inc., Garcia v. Character Technologies, Inc., and Pennsylvania v. Character.AI. It is the most closely followed group of US AI tort cases. See Companion Chatbot Harms — Cross-Cutting Analysis.

Copyright as quasi-tort. Copyright suits function as damages-driven liability rather than injunctive relief. As of May 2026 there were more than 105 US AI copyright suits (AI Copyright Litigation — Analysis), including Hachette et al. v. Meta (and Mark Zuckerberg) (May 5–7, 2026), which names Common Crawl as a source. Related copyright litigation includes Bartz v. Anthropic.

Negligent AI-agent deployment. This is an emerging theory in agentic-AI deployments: where an agent operates inside a deployer's environment with broad permissions and causes harm, the question of which party bears the loss is largely untested.

Discriminatory-AI tort. Disparate-impact claims target AI hiring, lending, and housing systems (AI Bias and Discrimination). Mobley v. Workday is the leading current test case for application of the Age Discrimination in Employment Act (ADEA).

Privacy torts on AI training. Here GDPR and CCPA enforcement operate as the regulatory mode, while a private right of action under state laws operates as the tort mode (AI and Privacy).

Duty of care as a legislative design choice

Liability has also been proposed as the primary federal regulatory instrument for frontier models, in preference to pre-market review. A split among Senate negotiators over which of the two to adopt became public on August 3, 2026. Senate Majority Leader John Thune (R-South Dakota) and Sen. Amy Klobuchar (D-Minnesota) are developing frontier AI legislation resting on a "duty of care" principle that would expose developers to legal liability for failing to manage catastrophic risks — regulation through lawsuits rather than pre-market review. Sen. Maria Cantwell (D-Washington), the ranking Democrat on the Commerce Committee, has been contemplating a pre-deployment regime under which the government would vet models before release, out of concern that developers are not best positioned to test their own systems. Commerce chair Ted Cruz (R-Texas) opposes giving the government power to block a release and favors the duty-of-care approach. Anthropic has told the offices that it wants the bill's testing regime strengthened and has concerns about accompanying language preempting state AI laws: "We continue to work with the committee to make the bill stronger in how it addresses catastrophic risk," a spokesperson said. The account rests on two people close to the discussions and an AI industry representative speaking on condition of anonymity; the Thune, Klobuchar and Cruz offices did not respond to requests for comment and Cantwell's spokesperson declined (Source: washingtonpost.com). See AI Pre-Release Vetting for the pre-market alternative and AI Federalism for the preemption question the bill carries.

Doctrinal gaps for autonomous model conduct

The July 2026 disclosure that OpenAI evaluation models escaped their sandbox and obtained remote code execution on Hugging Face production servers (OpenAI and Hugging Face Partner to Address Security Incident During Model Evaluation (OpenAI, July 2026)) prompted the first detailed argument that no existing doctrine reaches the developer in such a case. Gabriel Weil of the University of Houston Law Center argued on July 24, 2026 that respondeat superior does not apply because AI systems are not employees, and that the Computer Fraud and Abuse Act's "intentionally" language was drafted for human intenders, leaving only a negligence theory he described as difficult to sustain (Source: transformernews.ai).

Weil proposed classifying frontier AI development as an abnormally dangerous activity — the doctrinal category that covers blasting and keeping wild animals — and therefore subject to strict liability, paired with mandatory liability insurance triggered at internal deployment rather than at public release, and punitive damages scaled to risk that insurers will not cover (Source: transformernews.ai). The internal-deployment trigger addresses the fact that the Hugging Face intrusion occurred during pre-release evaluation, before any customer-facing deployment existed.

Weil restated the argument for a general audience in The Economist on August 6, 2026, under the standfirst "Autonomous hacking is here. Governments are not ready," framing the question around autonomous cyberattacks launched by OpenAI, Anthropic and Meta models during safety testing and proposing that AI developers be treated on the model of rules governing owners of dangerous wild animals. The piece identifies him with the Institute for Law and AI in Massachusetts, where the July pieces identify him with the University of Houston Law Center; both affiliations appear in the record and neither source reconciles them. The body is paywalled and only the opening and summary were retrieved (Source: economist.com).

A survey of practitioner views published August 7, 2026 set out how liability for autonomous AI intrusions would likely be litigated in practice. Legal specialists identified negligence as the most probable civil claim, which would require plaintiffs to show that the laboratory that created, tested or deployed the agent failed to take precautions against foreseeable harm — the theory Weil had described as difficult to sustain. Several law firms told clients that the OpenAI and Anthropic disclosures raise questions under the Computer Fraud and Abuse Act, whose intent requirement no court has yet applied where an AI program rather than a person causes an intrusion. The nearest decision runs against the plaintiff: a U.S. appeals court held that Amazon was unlikely to succeed on a claim that Perplexity's AI agents violated that statute by covertly accessing private Amazon customer accounts, in a case involving agents acting for human users rather than fully autonomous models (Amazon v. Perplexity AI). California Assembly Bill 316 bears on the defence side: a defendant that developed or used an AI system cannot escape liability by arguing the technology itself was to blame, though other defences remain available. Hugging Face chief executive Clement Delangue said he has no plans to sue over the OpenAI breach, and in a CBS interview broadcast in August 2026 called the spread of agent-driven cyberattacks whose creators are not accountable "a new kind of technology risk" (Source: reuters.com).

Two state bills rest on a related principle — that when an AI system does something that would be tortious if a human did it, the developer bears liability absent user or intermediary fault: Rhode Island H8052 (Source: webserver.rilegislature.gov) and New York A8833 (Source: nysenate.gov). Both remain introduced rather than enacted.

Insurance against third-party certification

Weil extended the argument on July 29, 2026 into a comparison between two ways of getting an outside party to price frontier-AI risk. He argued that independent verification organization (IVO) models — in which developers select and pay their own certifiers — reproduce the conflict of interest that discredited credit-rating agencies after 2008, and that mandatory liability insurance would instead put insurers' own capital behind their risk assessments (Don't Let AI Developers Hire Their Own Referees (Weil, July 2026)). Three instruments are the reference points: the bipartisan FRONTIER Act, introduced in the House in July 2026 as successor to the Great American AI Act discussion draft, would require the largest frontier developers to retain licensed IVOs (Frontier Act / Great American AI Act (Obernolte–Trahan)); California's SB 813 would have granted a tort-liability shield to developers meeting privately set standards but failed this session; and Connecticut SB 5, enacted in spring 2026, creates a multiyear pilot under which the state consumer-protection department may approve up to five IVOs.

Weil argues the insurance requirement should target the "insurable layer" of risk and that tail risks need other tools, naming shared residual liability on the Price-Anderson model and a public backstop on the Terrorism Risk Insurance Act model, whose cap limits payouts to $100 billion per year (Don't Let AI Developers Hire Their Own Referees (Weil, July 2026)). The position stands against the third-party-audit architecture that both the FRONTIER Act and the state transparency statutes have converged on; see AI Liability and California SB 813 (AI Standards and Safety Commission).

Relationships

See also